Stablecoin custody for MSBs: self custody, qualified custodian or regulated wallet provider?
Stablecoin custody for MSBs comes down to three models. We compare cost, control, recovery, insurance and examiner expectations, then give a decision rule.
- A licensed MSB has three workable custody models: self custody with hardware keys, a qualified custodian such as a chartered trust company or bank, and a regulated wallet provider running threshold signing under the MSB's own policy.
- The right answer for most MSBs is a split, not a single choice: a small operating float in a policy-controlled wallet sized for the day's payouts, and everything above that in cold storage or with a custodian.
- Recovery, not theft, is the most common failure in self custody. If one officer holds the only backup, the firm has a single point of failure whatever the hardware says.
- Examiners ask for a wallet address inventory tied to the ledger, a signing authority matrix, daily on-chain reconciliations and the custody agreement's insolvency clause. Prepare these before the first exam, not during it.
- Insurance certificates need reading. Custodian crime cover is usually an aggregate limit shared across all clients and often excludes hot wallets and authorised but fraudulent instructions.
Stablecoin custody for MSBs comes down to three workable models: self custody with hardware keys held by the firm's own officers, a qualified custodian such as a chartered trust company or bank, or a regulated wallet provider that runs threshold signing under the MSB's transaction policy. No single model suits every balance, so the practical answer for most licensed money service businesses is a split: a small operating float in a policy-controlled wallet, and anything above that in cold storage or with a custodian. This article compares the three models on cost, control, recovery, examiner expectations and insurance, and closes with a decision rule based on balance size and daily volume.
What are the three custody models available to a licensed MSB?
Self custody means the MSB generates and holds its own private keys. In practice this is a hardware signing device or a hardware security module, ideally in a multi-signature or threshold arrangement in which two of three named officers must approve any transfer. The MSB is the only party that can move funds, and the only party that can lose them.
A qualified custodian is a regulated third party that holds keys on the MSB's behalf under a written custody agreement. In the United States this usually means a state-chartered trust company or a national bank. The OCC's Interpretive Letter 1183 in 2025 reaffirmed that national banks may provide crypto-asset custody, which has widened the field of bank custodians willing to onboard a non-bank MSB. The MSB sends instructions; the custodian signs. Assets should be segregated on the custodian's books and, in the better arrangements, held in dedicated on-chain addresses per client rather than in an omnibus wallet.
A regulated wallet provider sits between the two. The provider supplies wallet infrastructure, usually multi-party computation (MPC), in which the key is split into shares held by the MSB, the provider and often a third backup party, so that no single party can sign alone. The MSB keeps a share and defines the transaction policy; the provider enforces it. Whether the provider is itself licensed, and in which jurisdiction, matters a great deal.
- Ask who physically holds enough key material to sign a transaction without anyone else, because that party carries the loss.
- Ask who can freeze an outbound transfer after the MSB has approved it, because that party controls operational risk.
- Ask which regulator the key holder reports to, and whether that regulator has ever examined the custody function.
- Ask what the contract says happens to the assets if the key holder becomes insolvent.
- Ask how long a withdrawal takes from instruction to on-chain confirmation, because a custodian that settles in hours undoes the reason for using stablecoin rails.
How do cost and control differ between the models?
Self custody looks cheap and is not. The hardware is inexpensive. The real cost is people: at least three officers who can sign, a documented key ceremony for generating and backing up the keys, a secure location for the backup shares, and the operational drag of a signer being unavailable when a payout queue is building. A firm that runs a two-of-three multi-signature wallet with two signers in the same office has bought hardware, not resilience.
A qualified custodian charges in the way institutional custodians generally charge: a fee on assets under custody, per-transaction fees, and often a minimum. Control is lower. Withdrawal windows, address allow-listing with a waiting period, and cut-off times are common, and each of them is a deliberate control on the custodian's side. For a reserve balance that is fine. For an operating float that must pay out in minutes, a custodian's cut-off time becomes the MSB's settlement time.
A regulated wallet provider usually charges a platform subscription plus per-transaction pricing. Control is high and granular: address allow-lists, velocity limits per hour and per day, dual approval above a threshold amount, time locks on new destination addresses, and separate policies per wallet. This is where the operating float belongs for a firm with meaningful daily volume. The cost that does not appear on the invoice is concentration: the provider's outage is the MSB's outage, and its policy engine becomes a control the MSB must evidence to an examiner.
What happens when a key is lost or an employee leaves?
In self custody the most common loss is not theft but a broken recovery path. The seed phrase or backup shares must be stored in geographically separate locations, and a restore must be tested at least annually with a witness present and a record kept. When a signer leaves the firm, revoking a building badge does nothing on chain. The keys must be rotated, which means creating a new signer set, moving funds to a new address set, and then updating every counterparty allow-list and every regulator filing that named the old addresses.
With a custodian, recovery is the custodian's problem by contract, but the MSB still owns the diligence. Ask for the custodian's SOC 1 and SOC 2 Type II reports and read the sections on key generation and backup. Then read the insolvency clause: are the assets held in trust for the MSB and bankruptcy remote, or would the MSB be an unsecured creditor? Nothing else in the agreement matters as much.
A wallet provider using MPC can reshare the key without moving funds, which makes signer rotation a policy change rather than a treasury operation. The diligence question is who holds the recovery share, in what form, and how the MSB retrieves it if the provider ceases to operate. A provider that cannot answer in writing has not solved recovery; it has moved it.
The operating wallet is a till, not a vault. Size it for the day's payouts, and put everything else somewhere that takes two people and a recorded phone call to open.
What will an examiner ask about custody?
A federal BSA examination of an MSB concentrates on the AML programme, but state money transmitter examiners, and FINTRAC in Canada, also look at safeguarding of funds and at the financial condition of the licensee. A number of US states expect that virtual currency owed to customers is held in the same type and amount, so a firm that owes customers USDC should be able to show USDC, not a bank balance that could buy USDC. Check the exact wording in each state licence. The GENIUS Act, signed on 18 July 2025, governs payment stablecoin issuers and their reserves; it does not relieve an MSB of its own safeguarding obligations for the stablecoins it holds.
- A wallet address inventory that maps every address to a ledger account, a purpose (operating, reserve, fee, customer omnibus) and a custody model.
- A key management policy and a signing authority matrix naming who can approve what amount, with evidence of the last access review.
- Daily reconciliations between the sub-ledger and on-chain balances, with a record of every break and how it was cleared.
- The custody agreement, the insurance certificate, the custodian's most recent assurance reports and the MSB's own vendor risk assessment.
- An incident log covering any failed signing, lost device, rejected transaction or address rotation, with dates and sign-off.
- Evidence that the model in use matches what the licence application described, or a record of the change notification sent to the regulator.
What does insurance actually cover?
Custodian insurance is usually a crime or specie policy covering theft of key material from cold storage, and the limit is typically an aggregate shared across all of the custodian's clients rather than a per-client amount. Hot wallet coverage is often smaller or absent. Policies commonly exclude losses caused by the client's own compromised credentials and losses from an authorised but fraudulent instruction, which is the scenario that occurs most often in practice. The MSB's own cyber and crime policies may exclude digital assets altogether unless an endorsement has been added.
The diligence is short and specific. Obtain the certificate. Note the aggregate limit and the number of clients it covers. Confirm whether the MSB is a named loss payee. List the exclusions and map each to the MSB's own controls. For a wallet provider, establish whether the cover applies to the provider's key share only, which is common, or to the whole wallet. An examiner who asks about insurance is testing whether the firm has read the policy, not whether the policy exists.
How should an MSB decide by balance size and volume?
Three variables settle the question: the size of the float relative to the firm's own capital, the velocity of daily payouts, and the number of staff who can genuinely act as independent signers. Balance size decides where the reserve lives. Volume decides how the operating float is controlled. Signer count decides whether self custody is available at all.
The rules that follow are stated without thresholds on purpose, because the right threshold depends on the licence conditions, capital position and corridor mix of the firm applying them. If the float is small enough that a total loss would not threaten the licence or the firm, and there are at least three independent signers, self custody with hardware multi-signature is acceptable, provided the key ceremony and restore test are documented. If the float exceeds that level but daily payouts are few, hold the reserve with a qualified custodian and keep a single small hot wallet for operations. If daily payouts are frequent, run the operating float in a regulated wallet provider with a policy engine, and automate sweeps of any excess to the custodian at a fixed time each day. If the firm settles in more than one stablecoin or on more than one chain, prefer a provider whose policies span all of them over several parallel self custody arrangements. If the licence requires like-kind holdings, place custody with an entity that can produce an attestation at period end.
Whatever the model, the split matters more than the vendor. A firm that can show an examiner a small, policy-controlled till, a separately held reserve, a daily reconciliation and a tested recovery path has answered the custody question.
Where StableNet fits
StableNet, built by SpendTheBits, is a cross border B2B payment and settlement platform for banks, credit unions, licensed money service businesses, exchange houses and remittance fintechs, and it is built on the principle that customers keep custody. Settlement runs in regulated stablecoins such as USDC and USDT on public blockchains, completing in minutes with on chain auditability, so an MSB can size its operating till for a single settlement cycle and keep its reserve wherever its custody decision places it. Every settlement leg carries ISO 20022 messaging, with pacs.008 customer credit transfers and pacs.002 status reports tracked end to end by UETR, which gives treasury a message-level record to reconcile against on-chain balances each day. Wallet screening, KYT and a tamper evident audit trail sit alongside the settlement flow, so the address inventory an examiner asks for has a control history behind it. SpendTheBits is a Bank of Canada registered payment service provider and a named finalist in the Swift Hackathon 2026 Technical Challenge.
See it on your corridors
Book a working session and we’ll map StableNet’s compliance and settlement to one of your live payment flows.